CVE-2025-40057
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-40057 is a vulnerability discovered in the Linux kernel's PTP (Precision Time Protocol) implementation, reported by syzbot and disclosed on October 28, 2025. The vulnerability affects the maxvclocksstore functionality when the argument max is too large for kcalloc to handle (NVD).

Technical details

The vulnerability occurs in the Linux kernel's PTP subsystem when handling max_vclocks values. Specifically, the issue arises when the argument max is too large for the kcalloc function to handle properly, requiring an extension of the guard to prevent values that exceed kcalloc's capacity (NVD, Ubuntu).

Impact

The vulnerability affects multiple Linux distributions and kernel versions, with Ubuntu assigning it a Medium priority. Several kernel versions across different distributions are marked as vulnerable, including Ubuntu 24.04 LTS noble and 22.04 LTS jammy in various configurations (Ubuntu).

Mitigation and workarounds

The vulnerability has been resolved through patches in various Linux kernel versions. Some distributions have already implemented fixes, while others are marked as not affected or have superseded the vulnerable versions with updated kernel releases (Ubuntu, Debian).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-5.15
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-raspi
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management